For those who didn't follow the link: malware is using account profiles on socnet servers (specifically mentions #Mastodon) to direct their software to command and control servers. If you think about it, it means that the C2 servers themselves need not be hard-coded into the malware infector software, as they can update the social network site's profile links if a particular C2 server is taken down.